Aggregator
CLOP
5 months 3 weeks ago
cohenido
CLOP
5 months 3 weeks ago
cohenido
CLOP
5 months 3 weeks ago
cohenido
CLOP
5 months 3 weeks ago
cohenido
CVE-2011-4040 | NJStar NJStar Communicator 3.0.11818 memory corruption (VU#819630 / EDB-18196)
5 months 3 weeks ago
A vulnerability was found in NJStar NJStar Communicator 3.0.11818. It has been declared as very critical. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2011-4040. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-0467 | Apple Mac OS X 10.4.8 symlink (VU#363112 / EDB-3219)
5 months 3 weeks ago
A vulnerability was found in Apple Mac OS X 10.4.8 and classified as critical. Affected by this issue is some unknown functionality in the library library/logs/crashreporter/. The manipulation leads to symlink following.
This vulnerability is handled as CVE-2007-0467. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40332 | idcCMS 1.35 moneyRecord_deal.php?mudi=delRecord cross-site request forgery
5 months 3 weeks ago
A vulnerability was found in idcCMS 1.35. It has been classified as problematic. Affected is an unknown function of the file /admin/moneyRecord_deal.php?mudi=delRecord. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2024-40332. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-40333 | idcCMS 1.35 softBak_deal.php?mudi=del&dataID=2 cross-site request forgery
5 months 3 weeks ago
A vulnerability was found in idcCMS 1.35. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/softBak_deal.php?mudi=del&dataID=2. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-40333. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-40336 | idcCMS 1.35 Image Advertising Management cross site scripting
5 months 3 weeks ago
A vulnerability classified as problematic has been found in idcCMS 1.35. This affects an unknown part of the component Image Advertising Management. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-40336. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-28828 | Checkmk up to 2.0.0p39/2.1.0p44/2.2.0p28/2.3.0p7 cross-site request forgery
5 months 3 weeks ago
A vulnerability classified as problematic was found in Checkmk up to 2.0.0p39/2.1.0p44/2.2.0p28/2.3.0p7. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2024-28828. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-40334 | idcCMS 1.35 serverFile_deal.php?mudi=upFileDel&dataID=3 cross-site request forgery
5 months 3 weeks ago
A vulnerability was found in idcCMS 1.35. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/serverFile_deal.php?mudi=upFileDel&dataID=3. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2024-40334. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-27095 | Decidim up to 0.27.5/0.28.0 Record cross site scripting (GHSA-529p-jj47-w3m3)
5 months 3 weeks ago
A vulnerability was found in Decidim up to 0.27.5/0.28.0 and classified as problematic. This issue affects some unknown processing of the component Record Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-27095. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-32469 | Decidim up to 0.27.5/0.28.0 GET Parameter per_page cross site scripting (GHSA-7cx8-44pc-xv3q)
5 months 3 weeks ago
A vulnerability was found in Decidim up to 0.27.5/0.28.0. It has been classified as problematic. Affected is an unknown function of the component GET Parameter Handler. The manipulation of the argument per_page leads to cross site scripting.
This vulnerability is traded as CVE-2024-32469. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38354 | hackmdio codimd up to 2.5.3 HTML Tag Name HTML injection (GHSA-22jv-vch8-2vp9)
5 months 3 weeks ago
A vulnerability was found in hackmdio codimd up to 2.5.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component HTML Tag Handler. The manipulation of the argument Name leads to HTML injection.
This vulnerability is known as CVE-2024-38354. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CLOP
5 months 3 weeks ago
cohenido
CLOP
5 months 3 weeks ago
cohenido
CLOP
5 months 3 weeks ago
cohenido
ChatGPT SSRF 漏洞迅速成为攻击者首选攻击载体
5 months 3 weeks ago
安全客
【安全圈】伪装成安全文档查看器的 DocSwap 恶意软件对全球安卓用户发动攻击
5 months 3 weeks ago
关键词恶意软件一场名为 “DocSwap” 的复杂恶意软件攻击活动浮出水面,它伪装成一款合法的文档安全与查看应